CVE
- Id
- 11844
- CVE No.
- CVE-2005-0638
- Status
- Candidate
- Description
- xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
- Phase
- Assigned (20050304)
- Votes
- None (candidate not yet proposed)
- Comments